Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3p64-r56c-8fcp

больше 4 лет назад

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

EPSS: Низкий
github логотип

GHSA-3p64-qffv-3m42

больше 2 лет назад

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3p64-6gvh-82v5

около 1 месяца назад

MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p64-362g-h8x8

больше 1 года назад

Out-of-bounds read in appending text paragraph in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p64-2ppg-fm8m

почти 4 года назад

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 all versions allows a remote unauthenticated attacker to disclose or tamper with sensitive information. As a result, unauthorized users may obtain information about project files illegally.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3p63-xccw-wppw

больше 1 года назад

A vulnerability has been found in PHPGurukul e-Diary Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /search-result.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3p63-fm6g-x8fh

больше 4 лет назад

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

EPSS: Низкий
github логотип

GHSA-3p63-23m4-gmcp

больше 4 лет назад

FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p62-pjv2-mchq

почти 2 года назад

The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3p62-p8gh-rh2w

5 месяцев назад

A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element is the function is_safe_path of the file src/code_mcp/server.py of the component MCP File Handler. Such manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3p62-jm9h-gf52

больше 4 лет назад

An undisclosed vulnerability in CLM applications (including IBM Rational Collaborative Lifecycle Management 4.0, 5.0, and 6.0) with potential for failure to restrict URL Access. IBM X-Force ID: 123661.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p62-6fjh-3p5h

около 3 лет назад

Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3p62-42x7-gxg5

больше 2 лет назад

Grafana User enumeration via forget password

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3p62-3xx8-qq46

больше 4 лет назад

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN messages that reset a finite state machine, aka Bug ID CSCup62293.

EPSS: Низкий
github логотип

GHSA-3p62-2p5c-mgqj

больше 2 лет назад

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p5x-m36j-2v3m

4 месяца назад

Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3p5w-c6fg-w249

больше 4 лет назад

On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p5w-29q3-9985

8 месяцев назад

A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p5v-chx4-4483

5 месяцев назад

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the configured firewall filter and access the control-plane of the device. On MX platforms with MPC10, MPC11, LC4800 or LC9600 line cards, and MX304, firewall filters applied on a loopback interface lo0.n (where n is a non-0 number) don't get executed when lo0.n is in the global VRF / default routing-instance. An affected configuration would be: user@host# show configuration interfaces lo0 | display set set interfaces lo0 unit 1 family inet filter input <filter-name> where a firewall filter is applied to a non-0 loopback interface, but that loopback interface is not referred to in any routing-instance (RI) configuration, which implies that it's used in the default RI. The issue can be observed with the CLI command: user@device> show firewall counter filter <filter_na...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p5v-c45v-mqqc

5 месяцев назад

Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACF Galerie 4: from n/a through 1.4.2.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p64-r56c-8fcp

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p64-qffv-3m42

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVSS3: 5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p64-6gvh-82v5

MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3p64-362g-h8x8

Out-of-bounds read in appending text paragraph in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3p64-2ppg-fm8m

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 all versions allows a remote unauthenticated attacker to disclose or tamper with sensitive information. As a result, unauthorized users may obtain information about project files illegally.

CVSS3: 9.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-3p63-xccw-wppw

A vulnerability has been found in PHPGurukul e-Diary Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /search-result.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3p63-fm6g-x8fh

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p63-23m4-gmcp

FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3p62-pjv2-mchq

The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3p62-p8gh-rh2w

A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element is the function is_safe_path of the file src/code_mcp/server.py of the component MCP File Handler. Such manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3p62-jm9h-gf52

An undisclosed vulnerability in CLM applications (including IBM Rational Collaborative Lifecycle Management 4.0, 5.0, and 6.0) with potential for failure to restrict URL Access. IBM X-Force ID: 123661.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p62-6fjh-3p5h

Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC

CVSS3: 10
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p62-42x7-gxg5

Grafana User enumeration via forget password

CVSS3: 6.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p62-3xx8-qq46

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN messages that reset a finite state machine, aka Bug ID CSCup62293.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p62-2p5c-mgqj

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p5x-m36j-2v3m

Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

CVSS3: 3.7
0%
Низкий
4 месяца назад
github логотип
GHSA-3p5w-c6fg-w249

On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p5w-29q3-9985

A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3p5v-chx4-4483

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the configured firewall filter and access the control-plane of the device. On MX platforms with MPC10, MPC11, LC4800 or LC9600 line cards, and MX304, firewall filters applied on a loopback interface lo0.n (where n is a non-0 number) don't get executed when lo0.n is in the global VRF / default routing-instance. An affected configuration would be: user@host# show configuration interfaces lo0 | display set set interfaces lo0 unit 1 family inet filter input <filter-name> where a firewall filter is applied to a non-0 loopback interface, but that loopback interface is not referred to in any routing-instance (RI) configuration, which implies that it's used in the default RI. The issue can be observed with the CLI command: user@device> show firewall counter filter <filter_na...

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3p5v-c45v-mqqc

Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACF Galerie 4: from n/a through 1.4.2.

CVSS3: 4.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу